HRDMNY
LegalPrivacyHome

HRDMNY Trust

Your book is the business. It is guarded like it.

A loan file holds the most sensitive information a borrower has. Here is exactly how the Service protects it, stated plainly.

Encryption everywhere

All data is encrypted in transit with TLS and at rest with AES-256. Card numbers never touch our systems; payments are processed end to end by Stripe, a certified PCI DSS Level 1 service provider.

Tenant isolation

Every organization is isolated at the database level with row-level security enforced on every table. Isolation is a database guarantee, not an application convention: interface permissions are convenience, the database is the enforcement.

Role-based access

Seats carry roles, organization administrators control membership, and machine access (connectors, tokens) runs with the scoped identity of whoever created it.

Audit trail

Automated and AI-taken actions are written to an organization-scoped audit log with timestamps and actor identity, so you can always read what Harmony did and when.

Backups and recovery

Automated backups with point-in-time recovery run continuously on our database infrastructure.

Hardened sessions

Authentication and session management are built on Supabase Auth, with secure cookie-based sessions and support for multi-factor authentication.

The infrastructure underneath

Harmony runs on infrastructure providers that maintain SOC 2 attestations, including Supabase (database, storage, and serverless compute), Vercel (application hosting), and Stripe (payments). AI processing runs on OpenAI's API services; telephony is carried by Twilio; e-signature execution runs on SignWell. The full subprocessor list is published in the Agreement.

Practices

  • Row-level security on every table, with grants reviewed as part of every schema change;
  • Organization-scoped access on every read and write path, including AI and connector access;
  • Sensitive identifiers stored encrypted with database-level access restricted;
  • HTML and document content sanitized on ingest;
  • Application routes closed by default: private surfaces are excluded from search indexing and unauthenticated access;
  • Verification gates on deployment: schema drift checks, type checks, and lint on every ship.

What we are honest about

HRDMNY itself does not yet hold a SOC 2 Type II attestation; an independent examination of HRDMNY's own controls is on our security roadmap, and until it is complete we claim our providers' attestations only for the layers they operate. We do not publish an uptime SLA on self-serve plans. When we state a certification on this page, we hold it; when a layer below us holds it, we say so.

Reporting a vulnerability

If you believe you have found a security issue, email security@hrdmny.com. We acknowledge reports promptly, we do not pursue good-faith researchers, and we appreciate the help.

© 2026 HRDMNY Technologies, LLCLegalPrivacySecurity